Part of The company brain: where your organization's knowledge lives
What is the EU AI Act? What applies now and what applies from December 2027
The AI Act regulates AI by risk. Which obligations already apply, what the Digital Omnibus postponed, and what your organisation needs to arrange now.

The EU AI Act (Regulation (EU) 2024/1689)1 is the European law that regulates AI by risk. The greater the impact of an AI application on people, the heavier the requirements. The law applies in phases. Some obligations are already in force, and the heaviest requirements for high-risk AI apply from 2 December 2027.
There is a lot of noise around the AI Act. One day you read that the law is "off the table", the next that every chatbot becomes a compliance project. Neither is true. This article explains what the law covers, what already applies and what your organisation actually needs to do.
The AI Act in one sentence
The AI Act sorts AI applications into four risk levels and attaches its own rules to each level. Separate rules apply to the makers of large AI models.
The four risk levels
| Level | Examples | What the law requires |
|---|---|---|
| Unacceptable risk | Social scoring, emotion recognition in the workplace, manipulation of vulnerable groups | Prohibited |
| High risk | AI in recruitment, employee assessment, credit scoring, education, critical infrastructure | Risk management, data quality, logging, human oversight, documentation |
| Limited risk | Chatbots, AI-generated text, images and audio | Transparency: people must know they are dealing with AI |
| Minimal risk | Spam filters, stock or demand forecasting, most internal analytics | No specific requirements beyond AI literacy |
Most AI in a typical organisation falls under limited or minimal risk. Think of asking questions of your own data, searching documents or flagging anomalies. That changes as soon as AI is used to assess people. Then you quickly end up in the high-risk category.
The greater the impact on people, the heavier the requirements.
What applies when
The Digital Omnibus (Regulation (EU) 2026/1744)2 changed the timeline. That change has applied since 27 July 2026.
| Date | What applies |
|---|---|
| 2 February 2025 | Prohibited AI practices and the AI literacy obligation |
| 2 August 2025 | Rules for providers of general-purpose AI models |
| 2 August 2026 | Transparency obligation: chatbots and AI content must be recognisable as AI |
| 2 December 2026 | Machine-readable marking for generative AI that was already running before August 2026; new bans on non-consensual intimate imagery and AI-generated child sexual abuse material |
| 2 December 2027 | High-risk AI under Annex III, such as recruitment, HR, credit and education |
| 2 August 2028 | High-risk AI embedded in regulated products (Annex I) |
Postponed is not cancelled. The delay only covers high-risk AI. The transparency obligation, the prohibitions and AI literacy all still apply.
The AI Act applies in phases. Only high-risk has been postponed.
Provider or deployer?
The AI Act distinguishes between the party that builds an AI system (the provider) and the party that uses it (the deployer). Most organisations are deployers. They don't build a language model, but use one for their own work.
That doesn't put you out of scope. As a deployer, you are responsible for, among other things:
- transparency towards the people who deal with your AI;
- AI literacy of employees who work with AI;
- for high-risk AI: human oversight, keeping logs, using the system according to its instructions, and informing affected employees.
Note: if you substantially modify an AI system or put it on the market under your own name, you may be treated as a provider yourself, with the heavier requirements that come with it.
When does your AI become high risk?
The question is not which technology you use, but what you use it for. The same language model can be minimal risk when it answers stock questions and high risk when it ranks job applicants.
Signs you are moving towards high risk:
- AI assesses, selects or ranks people;
- AI monitors the behaviour or performance of employees;
- AI helps decide whether someone gets access to credit, education or essential services;
- AI controls critical infrastructure.
A practical red line: never use communication data such as email and Teams to assess or monitor employees. It keeps you out of the heaviest category and protects the trust of your people.
Fines and supervision
The fines are substantial:
- up to €35 million or 7% of global annual turnover for prohibited practices;
- up to €15 million or 3% for most other violations.
In the Netherlands, the national implementing act (Uitvoeringswet AI-verordening) is in draft. It gives the Dutch Authority for Digital Infrastructure (RDI) and the Dutch Data Protection Authority (AP) a coordinating role, with sector regulators below them. Other member states have their own national set-up.
How the Netherlands organises supervision and which supervisor fits your organisation is covered in The AI Act in the Netherlands: which law applies and who supervises.
The AI Act does not stand alone
The AI Act overlaps with other legislation:
- The GDPR continues to apply as soon as personal data enters AI. A data protection impact assessment (DPIA) is often already required for sensitive applications, regardless of the AI Act.
- NIS2, implemented in the Netherlands as the Cybersecurity Act (Cyberbeveiligingswet), sets requirements for the security of the systems your AI runs on. What that asks of your data and AI layer is covered in NIS2 and the Dutch Cybersecurity Act: what your data and AI layer must be able to prove.
How to make all three manageable together is covered in AI governance for boards and supervisory boards: value, ethics and stop rules.
What to arrange now
- Create an AI register. Which AI is running, for what purpose, and who owns it? Don't forget Copilot licences and standalone tools.
- Classify each application by risk level, and record why. Repeat this when the use changes.
- Make AI recognisable. Since 2 August 2026, chatbots, AI answers and AI content must be recognisable as AI.
- Arrange AI literacy. Train employees and management in what AI can do, what it can't and where the risks are. That includes executives and supervisors. For the questions a supervisory board should ask about this every quarter, read Five questions every supervisory board should ask about AI each quarter. What that means per role is covered in AI literacy: what the AI Act asks of employees, management and supervisors.
- Draw a red line on assessing people, and record it in policy.
- Make sure you can prove what happens. Traceable answers, logging of questions and answers, and access managed per user. For high-risk AI it is mandatory, and in all other cases it is your best evidence.
That last point is not a legal question but a data question. If you can't trace where an answer came from, you can't prove your AI does what you promise. See also Implementing AI: why it almost always fails on your data.
Frequently asked questions
Does the AI Act apply if we only use ChatGPT, Claude or Copilot? Yes. You are then a deployer. The transparency obligation and AI literacy apply, and the risk category depends on what you use it for.
Has the AI Act been postponed? Only the requirements for high-risk AI, to 2 December 2027 and 2 August 2028. The prohibitions, the transparency obligation and AI literacy already apply.
Does the AI Act apply to SMEs? Yes. There are lighter documentation requirements for smaller organisations, but the core obligations apply to everyone who uses AI.
Who in the organisation is responsible? Using and classifying AI is an executive decision, not an IT judgement. Every application has one business owner.
Where do you start? With the AI register. Without an overview of what is running, you can't classify anything. Request a foundation scan.
Sources
Every claim in this article can be checked at the source.
- 1
- 2
- 3
Browse further
- Topic
- Concepts